An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/CanIPhish/Phishious

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.

dot-net-core-5 phishing secure-email-gateway security

Last synced: 11 Jul 2025

https://github.com/dolevf/graphql-cop

Security Auditor Utility for GraphQL APIs

auditing blue-team graphql hacking hardening penetration-testing red-team security

Last synced: 15 May 2025

https://github.com/corazawaf/coraza-caddy

OWASP Coraza middleware for Caddy. It provides Web Application Firewall capabilities

caddy caddyserver coreruleset go golang owasp security waf webapplicationfirewall

Last synced: 15 May 2025

https://github.com/narwhalacademy/zebra-crossing

Zebra Crossing: an easy-to-use digital safety checklist

digital-safety encryption online-harassment privacy safety security

Last synced: 29 Apr 2025

https://github.com/dev-sec/chef-os-hardening

This chef cookbook provides numerous security-related configurations, providing all-round base protection.

chef chef-cookbook devops hardening linux security

Last synced: 11 Aug 2025

https://github.com/quillhash/solidity-attack-vectors

This Repository contains list of Common Solidity SmartContract Attack Vectors. If you find any attack vectors missing, you can create a pull request and be a contributor of the project.

blockchain ethereum security solidity

Last synced: 05 Apr 2025

https://github.com/defenxor/dsiem

Security event correlation engine for ELK stack

elasticsearch elk logstash ossim security siem

Last synced: 09 Apr 2026

https://github.com/cilium/hubble-ui

Observability & Troubleshooting for Kubernetes Services

cilium ebpf graphical kubernetes observability reactjs security troubleshooting ui

Last synced: 14 May 2025

https://github.com/supercowpowers/zat

Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark

bro data-analysis kafka networking pandas python scikit-learn security spark zeek zeek-analysis

Last synced: 09 Apr 2025

https://github.com/mondoohq/cnspec

An open source, cloud-native security to protect everything from build to runtime

cloud-native compliance declarative kubernetes opensource policy policy-as-code security security-as-code

Last synced: 05 Jun 2026

https://github.com/cisco-sas/kitty

Fuzzing framework written in python

fuzzing security

Last synced: 14 Jan 2026

https://github.com/faucetsdn/poseidon

Poseidon is a python-based application that leverages software defined networks (SDN) to acquire and then feed network traffic to a number of machine learning techniques. The machine learning algorithms classify and predict the type of device.

automation docker faucet hacktoberfest machine-learning network-analysis network-forensics network-monitoring network-traffic network-traffic-capture network-traffic-classification networking pcap pcap-analyzer pcap-files sdn sdn-controller security software-defined-network

Last synced: 13 Dec 2025

https://github.com/ektrah/nsec

A modern and easy-to-use cryptographic library for .NET based on libsodium

aead aes-gcm blake2b chacha20-poly1305 crypto cryptography csharp curve25519 dotnet dotnet-core ed25519 encryption hash hkdf hmac libsodium security sha256 sha512 x25519

Last synced: 14 Jan 2026

https://github.com/github/entitlements-app

The Ruby Gem that Powers Entitlements - GitHub's Identity and Access Management System

entitlements iam security

Last synced: 14 May 2025

https://github.com/spatie/url-signer

Create and validate signed URLs with a limited lifetime

mail php security sign url

Last synced: 15 May 2025

https://github.com/zhaoweiho/SecurityManageFramwork

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management, account management, knowledge base management, security scanning automation function modules, and can be used for internal security management. This platform is designed to help Party A with fewer security personnel, complicated business lines, difficult periodic inspection and low automation to better achieve internal safety management.

exploits infosec pentesting scanner security security-audit vulnerability-assessment vulnerability-detection vulnerability-scanners

Last synced: 02 May 2025

https://github.com/we1h0/SecurityManageFramwork

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management, account management, knowledge base management, security scanning automation function modules, and can be used for internal security management. This platform is designed to help Party A with fewer security personnel, complicated business lines, difficult periodic inspection and low automation to better achieve internal safety management.

exploits infosec pentesting scanner security security-audit vulnerability-assessment vulnerability-detection vulnerability-scanners

Last synced: 02 Apr 2025

https://github.com/SuperCowPowers/zat

Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark

bro data-analysis kafka networking pandas python scikit-learn security spark zeek zeek-analysis

Last synced: 19 Jul 2025

https://github.com/ropfuscator/ropfuscator

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

clang compiler conference-paper conference-talk llc llvm llvm-pass obfuscation opaque-predicates return-oriented-programming return-to-libc security

Last synced: 05 Apr 2025

https://github.com/howsecureismypassword/hsimp

How Secure is My Password for your own website

password security strength

Last synced: 17 Apr 2025

https://github.com/igrigorik/istlsfastyet.com

Is TLS fast yet? Yes, yes it is.

security tls

Last synced: 27 Jan 2026

https://github.com/jpcertcc/sysmonsearch

Investigate suspicious activity by visualizing Sysmon's event log

elasticsearch kibana security stix stix2 sysmon

Last synced: 05 Apr 2025

https://github.com/JPCERTCC/SysmonSearch

Investigate suspicious activity by visualizing Sysmon's event log

elasticsearch kibana security stix stix2 sysmon

Last synced: 23 Apr 2025

https://github.com/lengjibo/netuser

使用windows api添加用户,可用于net无法使用时.分为nim版,c++版本,RDI版,BOF版。

hacker security windows

Last synced: 09 Oct 2025

https://github.com/zio/zio-json

Fast, secure JSON library with tight ZIO integration.

json performance scala security zio

Last synced: 14 May 2025

https://github.com/crev-dev/crev

Socially scalable Code REView and recommendation system that we desperately need. See http://github.com/crev-dev/cargo-crev for real implemenation.

audit code review security wot

Last synced: 25 Jan 2026

https://github.com/ReversecLabs/physmem2profit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

credential-theft pentesting red-team security windows

Last synced: 11 Jul 2025

https://github.com/reverseclabs/physmem2profit

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

credential-theft pentesting red-team security windows

Last synced: 17 Aug 2025

https://github.com/l3yx/Choccy

GitHub项目监控 && CodeQL自动扫描 (GitHub project monitoring && CodeQL automatic analysis)

codeql security static-analysis

Last synced: 04 Apr 2025

https://github.com/decoymini/DecoyMini

🐝 A highly scalable, safe, free enterprise honeypots 一款高可扩展、安全、免费的企业级蜜罐系统

attacker deception decoy ftp hacker honeynet honeypots honeytrap hw security simulation ssh telnet ti web

Last synced: 12 Jul 2025

https://github.com/paragonie/airship

Secure Content Management for the Modern Web - "The sky is only the beginning"

application-security cms cms-airship content-management free-software libsodium php postgresql secure secure-by-default security

Last synced: 22 Jul 2025

https://github.com/grapheneos/linux-hardened

Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than multiarch arm64 / x86_64 aren't in scope. Only tags have stable history. Currently maintained at https://github.com/anthraxx/linux-hardened.

linux privacy security

Last synced: 05 Apr 2025

https://github.com/tonyphipps/meerkat

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

analysis baseline blue forensics hunt incident log monitor purple recon red response scan security siem soc team threat threat-hunting triage

Last synced: 02 Apr 2025

https://github.com/evpo/EncryptPad

Minimalist secure text editor and binary encryptor that implements RFC 4880 Open PGP format: symmetrically encrypted, compressed and integrity protected. The editor can protect files with passwords, key files or both.

c-plus-plus cryptography encryption openpgp security text-editor utility

Last synced: 15 Mar 2025

https://github.com/GrapheneOS/linux-hardened

Minimal supplement to upstream Kernel Self Protection Project changes. Features already provided by SELinux + Yama and archs other than multiarch arm64 / x86_64 aren't in scope. Only tags have stable history. Currently maintained at https://github.com/anthraxx/linux-hardened.

linux privacy security

Last synced: 14 May 2025

https://github.com/TonyPhipps/Meerkat

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.

analysis baseline blue forensics hunt incident log monitor purple recon red response scan security siem soc team threat threat-hunting triage

Last synced: 05 Apr 2025

https://github.com/rc0r/afl-utils

Utilities for automated crash sample processing/analysis, easy afl-fuzz job management and corpus optimization

afl automation crash-reporting fuzzer fuzzing job-management python-3 security triage

Last synced: 11 Jan 2026

https://github.com/marshyski/quick-secure

Quickly secure UNIX/Linux systems

docker docker-security linux security security-hardening

Last synced: 25 Dec 2025

https://github.com/gacwr/openuba

A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [PRE-ALPHA]

analytics anomaly-detection cybersecurity datascience elasticsearch elk flask information-security machine-learning nodejs react security siem sklearn spark tensorflow threathunting uba ueba user-behaviour

Last synced: 18 Feb 2026

https://github.com/lengjibo/NetUser

使用windows api添加用户,可用于net无法使用时.分为nim版,c++版本,RDI版,BOF版。

hacker security windows

Last synced: 11 Jul 2025

https://github.com/ukncsc/device-security-guidance-configuration-packs

This repository contains policy packs which can be used by system management software to configure device platforms (such as Windows 10 and iOS) in accordance with NCSC device security guidance. These configurations are aimed primarily at government and other medium/large organisations.

android apple chromeos devices google ios macos mdm microsoft security ubuntu windows

Last synced: 15 May 2025

https://github.com/turbot/flowpipe

Flowpipe is a cloud scripting engine. Automation and workflow to connect your clouds to the people, systems and data that matters.

automation cloud devops flowpipe golang hacktoberfest low-code orchestration security workflow workflow-automation

Last synced: 15 May 2025

https://github.com/PagerDuty/security-training

Public version of PagerDuty's employee security training courses.

documentation pagerduty security team-security training

Last synced: 02 Apr 2025

https://github.com/intel/cc-oci-runtime

OCI (Open Containers Initiative) compatible runtime for Intel® Architecture

container containers docker kvm oci security virtual-machine virtualization

Last synced: 20 Apr 2025

https://github.com/pagerduty/security-training

Public version of PagerDuty's employee security training courses.

documentation pagerduty security team-security training

Last synced: 27 Oct 2025

https://github.com/ossf/fuzz-introspector

Fuzz Introspector -- introspect, extend and optimise fuzzers

fuzz-testing fuzzing security security-research testing vulnerability-analysis

Last synced: 15 May 2025

https://github.com/elkarbackup/elkarbackup

Open source backup solution for your network

backup elkarbackup rsnapshot rsync rsync-backups security ssh web webui

Last synced: 09 Mar 2026

https://github.com/lavabit/libdime

The DIME resolver library and command line utilities.

dark-mail email encryption messaging security

Last synced: 15 Jun 2025

https://github.com/keylime/keylime

A CNCF Project to Bootstrap & Maintain Trust on the Edge / Cloud and IoT

attestation cloud edge ima iot opensource security tpm virtualization

Last synced: 10 Apr 2025

https://github.com/ukncsc/Device-Security-Guidance-Configuration-Packs

This repository contains policy packs which can be used by system management software to configure device platforms (such as Windows 10 and iOS) in accordance with NCSC device security guidance. These configurations are aimed primarily at government and other medium/large organisations.

android apple chromeos devices google ios macos mdm microsoft security ubuntu windows

Last synced: 30 Apr 2025

https://github.com/Netflix-Skunkworks/policyuniverse

Parse and Process AWS IAM Policies, Statements, ARNs, and wildcards.

security

Last synced: 20 Mar 2025

https://github.com/michenriksen/birdwatcher

Data analysis and OSINT framework for Twitter

framework osint ruby security twitter-api

Last synced: 04 Apr 2025

https://github.com/flipkart-incubator/rta

Red team Arsenal - An intelligent scanner to detect security vulnerabilities in company's layer 7 assets.

nessus python security security-tools websecurity

Last synced: 05 Apr 2025

https://github.com/teamplanes/graphql-rate-limit

Add Rate Limiting To Your GraphQL Resolvers 💂‍♀️

graphql javascript nodejs security typescript

Last synced: 19 Jan 2026

https://github.com/spatie/laravel-ciphersweet

Use Ciphersweet in your Laravel project

laravel php privacy security

Last synced: 09 Feb 2026

https://github.com/ikkisoft/serialkiller

Look-Ahead Java Deserialization Library

deserialization java security security-hardening

Last synced: 02 Sep 2025

https://github.com/MandConsultingGroup/porch-pirate

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API endpoints and secrets committed to workspaces, collections, requests, users and teams. Porch Pirate can be used as a client or be incorporated into your own applications.

devsecops osint postman recon scanning secrets security

Last synced: 20 Apr 2025

https://github.com/OWASP/Python-Honeypot

OWASP Honeypot, Automated Deception Framework.

cybersecurity deception honeynet honeypot informationsecurity infosec owasp security

Last synced: 01 Apr 2025

https://github.com/panther-labs/panther-analysis

Built-in Panther detection rules and policies

cybersecurity python security siem

Last synced: 12 Aug 2025

https://github.com/righettod/poc-graphql

Research on GraphQL from an AppSec point of view.

graphql java security

Last synced: 31 Mar 2025

https://github.com/fkie-cad/fritap

Simplifying SSL/TLS traffic analysis for researchers by making SSL decryption effortless.

android android-https-capture binary-analysis frida hooking https linux network-analysis network-capture network-forensics security security-audit ssl ssldump tcpdump tls

Last synced: 09 Oct 2025

https://github.com/pac4j/play-pac4j

Security library for Play framework 2 in Java and Scala: OAuth, CAS, SAML, OpenID Connect, LDAP, JWT...

authentication authorization cas facebook java jwt ldap login logout mongodb oauth openid-connect play-framework saml scala security social-login sql twitter

Last synced: 11 Jan 2026

https://github.com/arun11299/cpp-jwt

JSON Web Token library for C++

cpp11 cpp14 cpp17 jwt jwt-header security

Last synced: 18 Oct 2025

https://github.com/lkrg-org/lkrg

Linux Kernel Runtime Guard

hardening integrity kernel linux security

Last synced: 13 Mar 2025

https://github.com/ivpn/desktop-app

Official IVPN Desktop app

ivpn openvpn privacy security vpn vpn-client wireguard

Last synced: 08 Apr 2025

https://github.com/basti-app/basti

✨ Securely connect to RDS, Elasticache, and other AWS resources in VPCs with no idle cost

automation aws cdk cicd cli cost-optimization hacktoberfest networking nodejs rds security vpc

Last synced: 15 Jan 2026

https://github.com/ikkisoft/SerialKiller

Look-Ahead Java Deserialization Library

deserialization java security security-hardening

Last synced: 11 Jul 2025

https://github.com/crytic/blockchain-security-contacts

Directory of security contacts for blockchain companies

blockchain directory email ethereum security

Last synced: 15 May 2025

https://github.com/0x0FB0/pulsar

Network footprint scanner platform. Discover domains and run your custom checks periodically.

collaboration cusomization dns integration osint paas recon scanner security

Last synced: 30 Mar 2025

https://github.com/lennolium/swiftguard

Anti-forensic macOS tray application designed to safeguard your system by monitoring USB ports.

anti-forensics defensive-security macos opsec physical-security security tampering-detection

Last synced: 16 May 2025

https://github.com/Lennolium/swiftGuard

Anti-forensic macOS tray application designed to safeguard your system by monitoring USB ports.

anti-forensics defensive-security macos opsec physical-security security tampering-detection

Last synced: 09 May 2025

https://github.com/RisingStack/protect

Proactively protect your Node.js web services

express nodejs security sql-injection xss

Last synced: 03 Apr 2025

https://github.com/risingstack/protect

Proactively protect your Node.js web services

express nodejs security sql-injection xss

Last synced: 04 Apr 2025

https://github.com/henrinormak/heimdall

Heimdall is a wrapper around the Security framework for simple encryption/decryption operations.

aes encrypted-messages ios rsa security swift

Last synced: 05 Apr 2025

https://github.com/domain-protect/domain-protect

OWASP Domain Protect - prevent subdomain takeover

aws bugbounty cloudflare dns owasp security security-tools serverless terraform

Last synced: 16 May 2025

https://github.com/henrinormak/Heimdall

Heimdall is a wrapper around the Security framework for simple encryption/decryption operations.

aes encrypted-messages ios rsa security swift

Last synced: 02 Aug 2025

https://github.com/meetrevision/revision-tool

A tool to personalize ReviOS to your needs

ame-wizard performance revios security tool tweaking usability windows

Last synced: 22 Apr 2026

https://github.com/samayo/bulletproof

Simple and secure image uploader in PHP

image image-upload image-uploader php php-image security upload

Last synced: 15 May 2025

https://github.com/ajinabraham/njsscan

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

appsec codereview codescanner devsecops expressjs jslint lint linter njsscan nodejs nodejsscan nodesecurity python sast security security-tools semantic static-analysis static-analyzer staticanalysis

Last synced: 14 May 2025

https://github.com/grapheneos/os-issue-tracker

Issue tracker for GrapheneOS Android Open Source Project hardening work. Standalone projects like Auditor, AttestationServer and hardened_malloc have their own dedicated trackers.

android grapheneos privacy security

Last synced: 16 May 2025

https://github.com/l4yton/RegHex

A collection of regexes for every possbile use

bugbounty regex security

Last synced: 06 Apr 2025

https://github.com/slowmist/eos-smart-contract-security-best-practices

A guide to EOS smart contract security best practices

blockchain eosio security smart-contracts

Last synced: 26 Jan 2026

https://github.com/abdoufermat5/unix-and-linux-sysadmin-notes

Unix and Linux system administration handbook by Evi Nemeth Garth Snyder Trent R. Hein Ben Whaley Dan Mackin

centos ci-cd debian devops docker freebsd linux redhat security shell-script sysadmin sysops unix

Last synced: 16 May 2025